Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency @fedify/fedify to v1.3.5 - autoclosed #231

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Dec 11, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@fedify/fedify (source) 1.3.1 -> 1.3.5 age adoption passing confidence

Release Notes

dahlia/fedify (@​fedify/fedify)

v1.3.5

Compare Source

Released on January 21, 2025.

  • Fixed a bug where CreateFederationOptions.allowPrivateAddress option had
    been ignored by the Context.lookupObject() method when it had taken
    a fediverse handle.

  • The lookupWebFinger() function became to silently return null when
    it fails to fetch the WebFinger document due to accessing a private network
    address, instead of throwing a UrlError.

v1.3.4

Compare Source

Released on January 21, 2025.

  • Fixed several security vulnerabilities of the lookupWebFinger() function.
    [[CVE-2025-23221]]

    • Fixed a security vulnerability where the lookupWebFinger() function
      had followed the infinite number of redirects, which could lead to
      a denial of service attack. Now it follows up to 5 redirects.

    • Fixed a security vulnerability where the lookupWebFinger() function
      had followed the redirects to other than the HTTP/HTTPS schemes, which
      could lead to a security breach. Now it follows only the same scheme
      as the original request.

    • Fixed a security vulnerability where the lookupWebFinger() function
      had followed the redirects to the private network addresses, which
      could lead to a SSRF attack. Now it follows only the public network
      addresses.

v1.3.3

Compare Source

Released on December 30, 2024.

v1.3.2

Compare Source

Released on December 18, 2024.

  • Fixed the default document loader to handle the Link header with
    incorrect syntax. [[#​196]]

Configuration

📅 Schedule: Branch creation - "* * * * 1-5" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot changed the title Update dependency @fedify/fedify to v1.3.1 Update dependency @fedify/fedify to v1.3.1 - autoclosed Dec 12, 2024
@renovate renovate bot closed this Dec 12, 2024
@renovate renovate bot deleted the renovate/fedify-fedify-1.x branch December 12, 2024 11:33
@renovate renovate bot changed the title Update dependency @fedify/fedify to v1.3.1 - autoclosed Update dependency @fedify/fedify to v1.3.1 Dec 18, 2024
@renovate renovate bot reopened this Dec 18, 2024
@renovate renovate bot force-pushed the renovate/fedify-fedify-1.x branch from 46d5b25 to 8a0c235 Compare December 18, 2024 12:13
@renovate renovate bot changed the title Update dependency @fedify/fedify to v1.3.1 Update dependency @fedify/fedify to v1.3.2 Dec 18, 2024
@renovate renovate bot force-pushed the renovate/fedify-fedify-1.x branch from 8a0c235 to a6da12d Compare January 20, 2025 16:43
@renovate renovate bot changed the title Update dependency @fedify/fedify to v1.3.2 Update dependency @fedify/fedify to v1.3.4 Jan 20, 2025
@renovate renovate bot force-pushed the renovate/fedify-fedify-1.x branch from a6da12d to 11bd0ff Compare January 21, 2025 13:51
@renovate renovate bot changed the title Update dependency @fedify/fedify to v1.3.4 Update dependency @fedify/fedify to v1.3.5 Jan 21, 2025
@renovate renovate bot changed the title Update dependency @fedify/fedify to v1.3.5 Update dependency @fedify/fedify to v1.3.5 - autoclosed Jan 21, 2025
@renovate renovate bot closed this Jan 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants